ai-gateway

Warn

Audited by Socket on May 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is plausible, but the key inconsistency is severe: a Vercel-branded gateway skill installs and relies on an unverified third-party CLI package not tied to Vercel’s documented tooling. Because that CLI receives the user’s AI Gateway API key and all prompt data, the skill presents a high supply-chain and credential-forwarding risk even though its user-facing function is coherent.

Confidence: 89%Severity: 86%
Audit Metadata
Analyzed At
May 11, 2026, 07:16 PM
Package URL
pkg:socket/skills-sh/Vesely%2Fskills%2Fai-gateway%2F@0866b156f13dba7b5b518a90807f6f65b2216116